Skip to content
Trausto

Company

Company

RiskZone GmbH is a Swiss software company. We build, ship and operate a single product — Trausto — and we do it with an engineering team that has spent years inside industrial cybersecurity programmes. The platform turns that operational reality into a workflow one responsible person can run alone and defend in front of an audit.

The company

A Swiss software company, one product

CO1

Who builds Trausto

A focused Swiss engineering team led by founder and managing director Mathias Pfister, headquartered in Rothenburg LU. Practitioner backgrounds in OT / IACS security, secure software engineering, applied cryptography and regulated-industry programmes.

CO2

Where we sit

Headquartered, engineered, operated, supported and liable in Switzerland — that is the counterparty you sign with. We deliver across Europe.

CO3

One product, no side bets

Trausto is the company's single product. No consulting arm, no side business. A small team with no sideshows: whoever builds Trausto also answers your support request.

Risk logic

How Trausto reasons about risk

Industrial risk decisions need a visible chain of reasoning: from operational reality to business impact, evidence and accountable human judgement.

Trausto starts with how the plant actually works: zones, conduits, trust boundaries, dependencies, roles and operational constraints. The model is not a detached scorecard; it is a structured explanation of why a scenario matters in a specific environment.

This makes decisions easier to challenge and defend. A risk is tied to the dependency that creates impact, the evidence that supports the assessment and the controls that can realistically reduce exposure.

  1. 01

    Map operational reality

    Assets are interpreted in context: which process they support, which zone they belong to and which trust boundary a conduit crosses.

  2. 02

    Evaluate mission impact

    Risk is weighed against continuity, safety and regulated obligations, not only against isolated asset loss or technical severity.

  3. 03

    Keep judgement reviewable

    AI-assisted suggestions remain advisory. Engineers keep authority, decisions stay attributable and relevant reasoning can be reviewed or exported.

Doctrine

Engineering Principles

These principles are product controls, not slogans. They shape how Trausto handles data, releases features and earns trust with regulated customers.

  1. P01

    Treat shared infrastructure as untrusted by default.

  2. P02

    Prefer cryptographic guarantees over policy promises.

  3. P03

    Design every feature to reduce operational burden or audit risk.

  4. P04

    Make critical decisions reviewable, attributable and exportable.

Compliance

Compliance posture & roadmap

We do not over-claim certifications. Here is where we are today, what we are working toward, and what is already available on request.

NOW

Today

Aligned to revFADP / nFADP, GDPR data minimisation, EU CRA, NIS2 and ENISA industrial cybersecurity guidance. IEC 62443 FR1–FR7 control mapping is part of the product.

NEXT

On the roadmap

Three pieces of independent evidence, in this order: an external penetration test of the platform, a cryptography whitepaper reviewed outside the company, and certification against ISO/IEC 27001. We will name dates here once they are booked — not before.

ASK

Available on request

Security architecture deck, vendor due-diligence questionnaire and reference contractual schedules for regulated operators. The technical whitepaper no longer sits here — it is published on the security model page.

See Trausto against your own zones

Bring one real site — your zones, conduits and security level targets (SL-T). In a single technical session we show how Trausto turns it into audit-ready IEC 62443 evidence, with your assessment content encrypted before it ever leaves the browser.